Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

A revisit of remote Spectre attacks on Cloudflare Workers

Blog post from Cloudflare

Post Details
Company
Date Published
Author
-
Word Count
3,446
Company Posts That Month
38
Language
English
Hacker News Points
-
Post removed?
No
Summary

Cloudflare reassessed remote Spectre risks in its Workers platform after advances in attack-stabilization techniques and discovered that a limitation in its Dynamic Process Isolation (DyPrIs) defense enabled a controlled end-to-end cross-tenant memory-leak demonstration in production. Researchers overcame frozen local timers, shared-resource noise, cache-eviction challenges, and execution limits by combining speculative type-confusion gadgets, cache-state amplification using the L1 cache’s PLRU policy, remote WebSocket-based timing, co-location through Worker subrequests, and persistent Durable Objects. The proof of concept leaked a deliberately planted JWT token from a co-located Worker at up to 12 bits per second with more than 99% accuracy, substantially faster than an earlier attack, although Cloudflare found no evidence of exploitation. The attack avoided DyPrIs detection because isolation occurred only after invocation completion and I/O-heavy WebSocket activity distorted its hardware-counter detection metrics. Cloudflare reports that the issue has already been mitigated through improvements to DyPrIs, deployment of the V8 memory sandbox, and hardware-assisted in-process isolation using Memory Protection Keys, which creates stronger boundaries between isolate heaps while not fully eliminating the broader class of Spectre-related risks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.